Chief Information Security Officer
TheRole
Lead
the organisation's cybersecurity and information security programme, ensuring
the confidentiality, integrity,andavailabilityofinformationassetsacrossaregulatedfinancialservicesenvironment.Defineand execute
security strategy, own and manage cyber risk within Board-approved appetite,
and maintain regulatory compliance within a cloud-native payments and stored
value facility (SVF) operation.
Theroleadvisesandrecommendsonsecurityrisk,withindependentauthoritytoescalateunresolvedriskto the CTO, CEO, and Board Risk Committee.
Operates within an approved annual security budget; spend proposals require
cost-benefit justification and are prioritised within the allocated envelope.
KeyResponsibilities
SecurityStrategy&Governance
- Defineandmaintainamulti-yearcybersecuritystrategyalignedwithbusinessgrowth,riskappetite, and regulatory
obligations.
- Establishandmaintaintheinformationsecuritypolicyframework,reviewedatleastannually.
- Maintainthecyberriskregisterandownthesecuritymaturityroadmapagainstarecognisedcontrol framework (NIST CSF, CIS Controls,
or ISO 27001).
- Ownthesecurityriskacceptanceandexceptionregister.
- Providesecurityleadershipandadvisorytoexecutivemanagementandregulatorystakeholders.
Threat&VulnerabilityManagement
- Directtheenterprisevulnerabilitymanagementprogramme,includingscanning,risk-based prioritisation, and remediation
SLA enforcement.
- Overseethepenetrationtestingprogrammeandensurefindingsareremediatedandretestedwithin defined timelines.
- Maintainthreatintelligencecapabilityrelevanttofinancialservicesandpayments,andtranslateit into detection and control
improvements.
SecurityOperations
- Overseesecuritymonitoring,detection,andresponsecapabilitiesincludingSIEM,EDR/XDR,and SOC operations
(internal or MSSP-managed).
- Own incident responseend
to end: maintain and test playbooks, run tabletop exercises, lead containmentandrecovery,andcoordinateregulatorynotificationwithinapplicabledeadlines.
- ManageidentityandaccessgovernanceincludingRBACdesign,privilegedaccessmanagement, joiner/mover/leaver controls,
and periodic access recertification.
- Defineandenforcedatalosspreventionanddataclassificationstandardsacrossallplatforms.
Regulatory&Compliance(FirstLine)
- MaintainoperationalcompliancewithPCIDSS,CBUAEtechnologyandinformationsecurityrisk requirements, UAE Information Assurance standards, and applicable
payment scheme obligations.
- Serveasprimarysecurityliaisontoexternalauditors,QSAs,andregulatoryexaminers.
- Ensuresecuritycontrolsaredocumented,evidenced,tested,andaudit-readyatalltimes.
- Trackandclosesecurity-relatedauditandexaminationfindingswithinagreedtimelines.
DataProtection&Privacy
- ImplementandmaintainsecuritycontrolssupportingUAEPDPLandapplicablecross-borderdata transfer obligations, in coordination with Legal and the
Data Protection Officer.
- Supportprivacyimpactassessmentsanddatabreachassessmentandnotification.
SecurityArchitecture
- Providesecurityinputtosystemdesign,changerequests,andnewinitiatives,andapprovesecurity architecture standards and
baseline configurations.
- Embedsecurity-by-designintheengineeringlifecycle,includingsecureSDLC,codereview, dependency scanning, secrets
management, and CI/CD pipeline controls.
- MaintaincloudsecurityposturestandardsfortheAWSestate.
CyberResilience
- Ensurecyberscenariosarerepresentedinbusinesscontinuityanddisasterrecoveryplanningand testing.
- Validatebackupintegrity,immutability,andrecoverycapabilityagainstdestructiveattack scenarios.
Third-PartySecurity
- Assessthesecuritypostureofprospectiveandexistingthirdpartiesandoutsourcedproviders, proportionate to criticality and data exposure.
- DefinesecurityrequirementsforvendorcontractsincoordinationwithLegalandProcurement.
- Managesecurityserviceproviders(MSSP,penetrationtestingfirms,consultants)againstdefined SLAs.
People&Capability
- Leadanddevelopthesecurityteam.
- Drivesecurityawarenessthroughtrainingprogrammesandphishingsimulations.
- Fosteraconstructivesecurityculturethatenablessafeescalationandreporting.
Reporting
- Monthlysecurityreporting totheCTO.
- StandingquarterlysecurityandcyberriskupdatetotheBoardRisk Committee.
- ImmediatenotificationofmaterialincidentstotheCTO,CEO,andChiefRisk Officer.
Requirements
Experience
- 10+yearsofprogressiveexperienceininformationsecurity,withatleast5yearsinaleadership role.
- Demonstratedexperienceinaregulatedfinancialservicesenvironment(banking,payments,
fintech, or SVF).
- Hands-onexperiencewiththePCIDSScompliancelifecycleinapaymentenvironment.
- Proventrackrecordofleadingincidentresponseduringlivesecurityevents.
- ExperiencemanagingSOCoperations(internalorMSSP)includingSIEM,EDR/XDR,andthreat intelligence.
- Strongunderstandingofcloudsecurity(AWSpreferred),containerandKubernetessecurity,and API security.
- Experiencewithregulatoryframeworks:CBUAEtechnologyandinformationsecurityrisk circulars, UAE IA, or equivalent.
- DemonstratedabilitytocommunicatesecurityrisktoexecutiveandBoard-levelaudiences.
- Experiencemanagingthird-partysecurityvendorsandserviceproviders.
- Experiencebuildinganddevelopingsecurityteams.
- Demonstratedabilitytodeliversecurityoutcomeswithinconstrainedbudgets,prioritisingrisk reduction per unit of spend.
Leadership&SoftSkills
- Strongstrategicthinkingwithabilitytotranslateriskintobusiness language.
- Abilitytoinfluencewithoutauthorityacrossengineering,product,andbusinessteams.
- Clearcommunicatorwhocanbriefexecutivesandregulatorsunderpressure.
- CollaborativeapproachwithEngineering,Operations,GRC,andbusinessstakeholders.
- Comfortableinfast-paced,scalingenvironmentswithevolvingpriorities.
Qualifications
- Bachelor'sdegreeinComputerScience,Cybersecurity,InformationTechnology,orarelatedfield, or equivalent professional experience.
- Industrycertificationsrequired(oneormore):CISSP,CISM,CISA,orISO27001LeadAuditor.
- Additionalcertificationsvalued:PCIP,OSCP,CCSK,CRISC,AWSSecuritySpecialty.
TechnologyEnvironment
AWS(Lambda,ECS,EKS,RDS,CloudFront,WAF),Kubernetes,Kafka,PostgreSQL,Java/SpringBoot,
React, React Native, Datadog, Microsoft 365/Entra ID, Terraform.
AdditionalConditions
- Participationinanon-callescalationrotaforsecurityincidents.
- Availabilityoutsidestandardhoursduringliveincidentsandmajorchangeevents.
- Appointmentsubjecttoenhancedbackgroundscreeningappropriatetoaregulatedfinancial services control function.
